Description
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
11.0.0
11.1.0
11.2.0
11.3.0
12.0.0
References
docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083